Purpose limitation
Personal information is collected and used for documented service, business and legal purposes.
Security at DuoKey
Protecting sensitive data starts with how we build, operate and govern our own technology. Security is integrated into DuoKey’s organisation, products and cryptographic architecture.
Governance
Security controls designed to be effective, consistent and auditable.
DuoKey establishes policies, assigns responsibilities, assesses risk and monitors the controls that protect our company, services and customers.
Security principles
How we approach security.
These principles guide how DuoKey protects its organisation, products and customers.
Access is limited to people with a legitimate business need and to the minimum permissions required for their role.
Identity, endpoint, network, application and cryptographic safeguards are layered to reduce reliance on any single control.
Security requirements apply across our people, suppliers, engineering practices, infrastructure and service operations.
We review risk, test safeguards and improve our security programme as technology, threats and customer needs evolve.
Security and compliance
DuoKey maintains an ISO/IEC 27001:2022-certified information security management system and has completed a TISAX® assessment. Additional assurance material is available through our Trust Center.
Data protection
Designed so that control does not depend on one system or one party.
DuoKey distributes cryptographic control, keeps encryption keys under customer authority, and makes sensitive operations auditable.
DuoKey uses secure Multi-Party Computation to distribute cryptographic operations across independent nodes. No single node needs to hold the complete key material.
Our products help organisations retain control of encryption keys while protecting sensitive workloads across cloud services, SaaS platforms and hybrid environments.
Access controls, lifecycle management and audit records provide visibility into sensitive cryptographic activity and support operational oversight.
Product security
Security throughout the product lifecycle.
Security is considered from architecture and implementation through release and production operation.
Engineering changes are reviewed, tested and delivered through controlled development and release processes.
Automated and targeted testing helps identify weaknesses in source code, dependencies, applications and infrastructure.
Potential vulnerabilities are assessed, prioritised and tracked through remediation according to their risk and impact.
Security-relevant events and service health are monitored to support investigation, response and continuous improvement.
Enterprise security
Protecting the organisation behind the product.
Operational safeguards protect DuoKey’s people, devices, suppliers and internal services.
Strong authentication, role-based access and timely provisioning and deprovisioning protect internal services.
Corporate devices are centrally managed with encryption, malware protection, security configuration and update controls.
Employees receive security awareness training and practical guidance for recognising and responding to threats.
Third parties are assessed according to their access, data handling and potential impact on critical services.
Data privacy
We process personal information for defined purposes, apply appropriate safeguards and support applicable data protection rights.
Personal information is collected and used for documented service, business and legal purposes.
Individuals can exercise applicable rights relating to access, correction, deletion, restriction and objection.
Personal information is retained only as needed, and service providers are expected to protect its confidentiality and security.
Responsible disclosure
Please report suspected vulnerabilities privately and include enough detail for our team to reproduce and assess the issue.